CVE-2024-9365

CVSS 3.0 Score 6.5 of 10 (medium)

Details

Published Mar 20, 2025
CWE ID 352

Summary

CVE-2024-9365 is a Cross-Site Request Forgery (CSRF) vulnerability affecting polyaxon/polyaxon version 2.4.0. Attackers can exploit this flaw to execute unauthorized actions in a victim's browser, including creating projects, model versions, artifact versions, and altering settings. This vulnerability poses a significant risk of data loss and service disruption. Users are strongly encouraged to update their polyaxon installation as soon as possible to mitigate this threat.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share